Design, Architectural Evaluation, and Feature Engineering Analysis of a Machine Learning-Based Network Intrusion Detection System Using Random Forest Ensemble

Walat Ali Ahmed : Duhok Polytechnic University

Abstract


In the modern network environment characterized by highly heterogeneous network architectures, the security landscape is dominated by a persistent and burgeoning threat scenario of extremely high complexity. Security systems based on signature detection are not efficient at protecting against new threats, and they are vulnerable to evasion strategies.

In this research, we propose a novel machine-learning network intrusion detection system (NIDS) designed for multiclass network attack classification based on a weighted Random Forest algorithm. The proposed model was tested experimentally on the well-known benchmark dataset KDDCUP99 that contained 494,021 network connections. We designed the preprocessing pipeline based on macro-class level categorical label mapping, ordinal attribute mapping, and Min-Max numerical normalization.

The evaluation was performed using the validation subset that was kept separate (i.e., an out-of-sample test) from the training process and consisted of 148,207 records. The proposed model achieved an overall accuracy of 99.97% in multiclass classification. We focus on discussing the severe class imbalance, and the experimental results indicate that our method is capable of achieving satisfactory predictive performance for minority classes, as the proposed classifier maintains a precision score as high as 90.91% for a rare attack class User-to-Root (U2R). Finally, we provide a complete comparison of the proposed approach with a set of state-of-the-art intrusion detection baselines.


Keywords


Network Intrusion Detection System (NIDS); Random Forest; Data Engineering; Cyber Security; Class Imbalance; Statistical Evaluation; Comparative Analysis.

Full Text:

PDF

References


Ahmad, I., Basheri, M., Iqbal, M. J., & Rahim, A. (2018). Performance comparison of support vector machine, random forest, and extreme learning machine for intrusion detection. IEEE Access, 6, 33789-33799.

Akuthota, U. C., & Bhargava, L. (2023). Evaluation of machine learning models for intrusion detection with the UNSW-NB15 dataset. 2023 IEEE Silchar Subsection Conference (SILCON), 1-5.

Alegre, G. E., & Cerna, P. D. (2024). Enhancing intrusion detection in education sector through advanced machine learning techniques: A comparative study. 2024 First International Conference for Women in Computing (InCoWoCo), 1-8.

AlZubi, M. I. (2019). Intensive pre-processing of KDD Cup 99 for network intrusion classification using machine learning techniques. Journal of Online Engineering, 13(2), 70-84.

Amor, N. B., Benferhat, S., & Elouedi, Z. (2004). Naive bayes vs decision trees in intrusion detection systems. In Proceedings of the 2004 ACM Symposium on Applied Computing (pp. 420–424).

Azhar, M., Perveen, S., Iqbal, A., & Lee, B. (2024). IDRandom-Forest: Advanced random forest for real-time intrusion detection. IEEE Access, 12, 113842–113854.

Bhati, B. S., Chugh, G., Al-Turjman, F., & Bhati, N. S. (2021). An improved ensemble based intrusion detection technique using XGBoost. Transactions on Emerging Telecommunications Technologies, 32(6), e4034.

Breiman, L. (2001). Random forests. Machine Learning, 45(1), 5–32.

Fauzi, F., Al-Khowarizmi, A. K., & Muhathir, M. (2020). The e-Business Community Model is Used to Improve Communication Between Businesses by Utilizing Union Principles. JITE (Journal of Informatics and Telecommunication Engineering), 3(2), 252-257.

Ghorbani, A. A. (2009). A detailed analysis of the KDD CUP 99 data set. In Second IEEE Symposium on Computational Intelligence for Security and Defense Applications (CISDA) (pp. 1–6).

Hosseinzadeh Aghdam, M., & Kabiri, P. (2016). Feature selection for intrusion detection system using ant colony optimization. International Journal of Network Security, 18(3), 420–432.

Korb, K. B. & Nicholson, A.E. (2011). Bayesian Artificial Intelligence. 2nd Edition. CRC Press: Boca Raton.

Lu, T., Huang, Y., Zhao, W., & Zhang, J. (2019). The metering automation system based intrusion detection using random forest classifier with SMOTE+ENN. In 2019 IEEE 7th International Conference on Computer Science and Network Technology (ICCSNT) (pp. 370–374).

Mehmood, T., & Rais, H. B. M. (2019). Machine learning algorithms in context of intrusion detection systems: A review. International Journal of Computer Science and Network Security, 19(3), 112–120.

Obeidat, I. M., Hamadneh, N., Alkasassbeh, M., & Almseidin, M. (2019). Intensive pre-processing of KDD Cup 99 for network intrusion classification using machine learning techniques. ZU Scholars, 2(1), 1–15.

Onyebueke, A. E., David, A. A., & Munu, S. (2023). Network intrusion detection system using XGBoost and random forest algorithms. Asian Journal of Pure and Applied Mathematics, 5(1), 321–335.

Pedregosa, F., & Varoquaux, G. (2011). Scikit-learn: Machine learning in Python. Journal of Machine Learning Research, 12, 2825–2830.

Pranto, M., Al-Turjman, F., & Reduced, D. (2022). Dimensionality reduction and hyperparameter optimization for intrusion detection on the KDD’99 dataset. Cybersecurity Informatics Journal, 4(2), 89–104.

Rababah, B., & Srivastava, S. (2020). Hybrid model for intrusion detection systems. arXiv, 1–10.

Revathi, S., & Malathi, A. (2013). A detailed analysis on NSL-KDD dataset using various machine learning techniques for intrusion detection. International Journal of Engineering Research & Technology, 2(12), 1848–1853.

Sow, T. H. (2025). Enhancing IDS performance through a comparative analysis of Random Forest, XGBoost, and Deep Neural Networks. Semaphore UQAR Research Corpus, 3(1), 1–45.

Tavallaee, M., Bagheri, E., Lu, W., & Ghorbani, A. (2009). A detailed analysis of the KDD CUP 99 data set. In IEEE Symposium on Computational Intelligence for Security and Defense Applications (pp. 1–6).

Taylor, O. E. (2021). Combining principal component analysis with random forest for advanced network anomaly classification. Journal of Cyber Security Tech, 5(3), 201–215.

UCI KDD Archive. (1999). The KDD Cup 1999 Dataset. http://kdd.ics.uci.edu/databases/kddcup99/kddcup99.html

Wu, S. X., & Banzhaf, W. (2010). The use of computational intelligence in intrusion detection systems: A review. Applied Soft Computing, 10(1), 1–35.

Zhang, M. (2025). Effectiveness evaluation of random forest, naive bayes, and support vector machine models for KDDCUP99 anomaly detection based on K-means clustering. ITM Web of Conferences, 70, 04010.

Zhang, J., Zulkernine, M., & Haque, A. (2008). Random-forest-based network intrusion detection systems. IEEE Transactions on Systems, Man, and Cybernetics, Part C (Applications and Reviews), 38(5), 649-659.




DOI: https://doi.org/10.30596/jcositte.v7i2.30793

Refbacks

  • There are currently no refbacks.